R211x-HP Flexfabric 11900 Fundamentals Command Reference
74
The FIPS mode supports only the interactive mode for setting a password.
Set a password if you configure local password authentication for temporary user role authorization.
It is a good practice to specify different passwords for different user roles.
Examples
# Set the password to 123456TESTplat&! for the user role network-operator.
<Sysname> system-view
[Sysname] super password role network-operator simple 123456TESTplat&!
# Set the password to 123456TESTplat&! in the interactive mode for the user role network-operator
<Sysname> system-view
[Sysname] super password role network-operator
Password:
Confirm :
Related commands
super authentication-mode
vlan policy deny
Use vlan policy deny to enter the user role VLAN policy view.
Use undo vlan policy deny to restore the default user role VLAN policy.
Syntax
vlan policy deny
undo vlan policy deny
Default
A user role has no access to any VLAN.
Views
User role view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
The vlan policy deny command denies the access of a user role to any VLAN.
To restrict the VLAN access of a user role to only a set of VLANs:
1. Use vlan policy deny to deny access to any VLAN.
2. Use permit vlan to specify accessible VLANs.
To perform any of the following operations, you must make sure the VLAN is permitted by the VLAN
policy of any user role that you are logged in with:
• Create, remove, or configure a VLAN.
• Enter its view.
• Specify the VLAN in a feature command.










